Details
Protection of log data includes assuring log data is not accidentally lost or deleted. Backing up log records to an unrelated system or onto separate media than the system the web server is actually running on helps to assure that, in the event of a catastrophic system failure, the log records will be retained.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Configure system backups to include the directory paths of all IIS 8.5 web server and website log files.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Audit and Accountability.This control applies to the following type of system Windows.
References
- 800-53|AU-9(2)
- CAT|II
- CCI|CCI-001348
- Rule-ID|SV-214406r508658_rule
- STIG-ID|IISW-SV-000116
- STIG-Legacy|SV-91393
- STIG-Legacy|V-76697
- Vuln-ID|V-214406